Guest User!

You are not Sophos Staff.

Restricted Advance Shell - examples of challenges

Hi Community contributors,

Starting Sophos Firewall v19, with the addition of many comprehensive logging enhancements in the GUI, and in-line with industry best-practices, access to the Advance Shell is restricted to licensed commercial versions of the product.

Partners and certified architect engineers have an option with Not-for-Resale license to set up labs or customer PoC with unrestricted advanced shell. Also, Sophos Support is able access the Advanced Shell via support access channel. Hence, in case of critical issues, support can still can access it.

Sophos Firewall has been incrementally improved since v18 with comprehensive logging enhancements in the GUI (Better search, filtering, configurations, SD-WAN logs, VPN logs, gateway logs etc). However, we acknowledge that Advance Shell restriction might have created challenges in certain database related configurations, especially for home users.

Please help us understand the specific examples of challenges you face due to this restriction - configurations where GUI and console tools are reaching the limits. We will suggest the possible workaround for the specific scenario. We will also plan and gradually improve the product for those scenario.

Sincerely,

Sophos Firewall Product Team

Parents Reply Children
  • I am a partner. Since UTM the Home version was a good reason for many to check out Sophos firewall products in detail and I'm sure Sophos won many customers and partners just because of this version no one else offers. Sure, as a partner we get NFR licenses for our own firewall, but do I want to tinker arround with our production network? No.  wrote that the support could still access the shell, but how should I interpret this? That the support is starting to actively support home users? Really?!

    I don't see the point in all of this, except you'd tell me right now that Sophos has some clear evidence that the Home version is used commercially in a bigger scale, which I can't imagine is the case, but who knows?

    If you would supply your partners and customers with an easy way to get NFRs for virtual devices, I'd probably be happy and leave you alone with this, though I still don't get the point.

  • Essentially Sophos as a company can still access the appliance in case of bug tracking or something. For example, a Home user discovers a bug in V19.0 and wants to report it. DEV can access the appliance and investigate this issue via SupportAccess. 

    From my point of view as the most activate person in the community by far (see leader board), the advanced shell is not needed in the majority of "threads". Simply because the product is in a state of having a simple UI to get the most common issues configured or debugged via GUI. And i am talking about a new installation / configuration of a home appliance. Most home users have a average use case of simple setups. And most likely, if you look at the threads by home users, there are certain configuration issues, which do not need any interaction with the CLI. Most likely if i point to "do a packet capture" they are most comfortable with the packet capture in the GUI. 

    Sophos Product management wants to gather open spots of still use cases, which the product does not cover (today). 

    There are valuable contributions to this thread already. 

    There are currently two different programs for Partners. The partner as a organisation can get NFR licenses for its own organisation. For example for the Firewall of the partner. Then there is a program for the education. If you are a Sophos Architect (you did the training and certification) you can get all Sophos products (and a 3 year Sophos Firewall subscription) for your own environment. 

  • Hi 

    I'm a Sophos XG Architect, where can i find those three year license you are talking about?

    Thanks.